Hot!FortiGate Out of Sync after device updates CRL

Author
malachykidd
New Member
  • Total Posts : 6
  • Scores: 0
  • Reward points: 0
  • Joined: 2015/09/06 15:52:16
  • Status: offline
2019/01/18 18:26:45 (permalink) FortiManager
0

FortiGate Out of Sync after device updates CRL

I've configured a pair of FortiGate 81E firewalls into a HA cluster, and I use them to terminate a set of auto-detect IPSEC tunnels.  To improve security, I use PKI to authenticate the tunnels, and I have configured the firewalls to download CRL updates using HTTP.  The firewalls currently run FortiOS 5.6.5, and FortiManager is 6.0.2.
 
Unfortunately, when the firewalls update the CRL, it causes them to register as Out of Sync in FortiManager.
 
Is there a way to prevent this?
 
Thank you.
#1
teddyko_FTNT
New Member
  • Total Posts : 2
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/01/25 09:43:26
  • Status: offline
Re: FortiGate Out of Sync after device updates CRL 2019/01/21 15:55:24 (permalink)
0
Is your Config Status or Policy Package Status going to "Out of Sync"?
 
Changes to the CRL should only affect Config Status. One possibility for Out of Sync status is your auto-update setting may be disabled. You can validate this by running the following CLI:
 
get system admin setting
#2
malachykidd
New Member
  • Total Posts : 6
  • Scores: 0
  • Reward points: 0
  • Joined: 2015/09/06 15:52:16
  • Status: offline
Re: FortiGate Out of Sync after device updates CRL 2019/01/22 13:14:20 (permalink)
0
teddyko
Is your Config Status or Policy Package Status going to "Out of Sync"?

 
Config Status.
 
teddyko
Changes to the CRL should only affect Config Status. One possibility for Out of Sync status is your auto-update setting may be disabled. You can validate this by running the following CLI:
 
get system admin setting



Auto-update is disabled.
 
I assume, then, that there is no mechanism within FortiManager to ignore or auto-update only the CRLs; that the solution is to enable auto-update for all devices.  That's fine, as I am the only person who manages the firewalls, though ideally there would be a way to ignore automatic, self-changing bits of configuration like that.
 
Thank you.
#3
malachykidd
New Member
  • Total Posts : 6
  • Scores: 0
  • Reward points: 0
  • Joined: 2015/09/06 15:52:16
  • Status: offline
Re: FortiGate Out of Sync after device updates CRL 2019/01/22 13:20:39 (permalink)
0
Well... I enabled auto-update, and FortiManager auto-updated the config, but then it set the root policy package status to Out of Sync, though there are no changes applied if I (re)install the policy package.  Not ideal.
#4
Jump to:
© 2019 APG vNext Commercial Version 5.5